:

TWITCH EXTENSION LEAKS OAUTH TOKENS TO BOT SERVICE

INDUSTRY DESK2 MIN READ
MON, SEP 14, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

A browser extension with 30,000 installs available on Chrome and Firefox stores transmits users' Twitch OAuth session tokens to a commercial bot service, exposing sensitive authentication credentials.

The extension, called Twitch Enhanced Viewer | JeetBot, operates through official browser marketplaces while secretly sending user authentication tokens to external servers. OAuth tokens grant access to Twitch accounts and associated data. When exposed, they allow attackers to impersonate users, access their accounts, and perform actions on their behalf without permission. What the extension does: Twitch Enhanced Viewer | JeetBot presents itself as a viewer enhancement tool. The extension collects Twitch OAuth tokens generated during normal user authentication and forwards them to a commercial bot service operated by a third party. Scale of exposure: With 30,000 installations across Chrome Web Store and Firefox Add-ons, the extension has potentially exposed tens of thousands of users' credentials. Each affected user's Twitch account remains at risk unless they revoke access. Security implications: Users who installed the extension should immediately revoke its access from their Twitch account settings. Affected individuals may also want to change their Twitch password as a precaution. The incident highlights risks associated with third-party browser extensions, even those available through official stores. Marketplace reviews and download counts do not guarantee security or legitimate behavior. Next steps: Browser store moderators should remove the extension if they have not already done so. Twitch may need to invalidate tokens associated with affected accounts or implement additional detection for suspicious token usage patterns. Users should verify installed extensions regularly and uninstall anything unnecessary. When granting extensions permission to access Twitch accounts, review what data they request and whether the requested permissions align with the extension's stated purpose.

■ SOURCES

Bleeping Computer

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

OpenAI's web-crawling bots were aware of a significant caching vulnerability in RubyGems before public disclosure, raising questions about vulnerability discovery and responsible disclosure practices.

2H AGOAI Desk

Attackers compromised HBO Max's official Reddit account to distribute malicious ads using ClickFix exploits. The campaign targeted Windows and macOS users with information-stealing malware.

2H AGOSecurity Desk

OpenAI has hundreds of contract workers reviewing real ChatGPT conversations and rating them to improve the model. The practice is enabled by default, requiring users to manually opt out.

3H AGOAI Desk

The Manhattan District Attorney's Office has seized 12 websites that created non-consensual deepfake content of celebrities, marking the largest legal action against harmful deepfake platforms to date. The sites collectively victimized approximately 1,200 people.

4H AGOIndustry Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.